CRITICAL🇵🇱 Wersja polska

CVE-2025-12106

CVSS 9.1v3.1pub. 2025-12-01upd. 2025-12-30

Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IP addresses

🤖 AI Analysis
How it works

The vulnerability results from insufficient argument validation (CWE-126 — buffer over-read) when processing IP addresses. An attacker can provide a specially crafted IP address input string, causing data to be read beyond the bounds of an allocated heap buffer. The operation requires no authentication or user interaction, significantly lowering the attack barrier.

Impact

An attacker can gain unauthorized access to sensitive data from the OpenVPN process memory (e.g., session keys, configuration data) and cause VPN service failure (denial of service). The combination of high impact on confidentiality and availability results in a CVSS score of 9.1.

Mitigation & patch

Refrain from using alpha/RC versions of branch 2.7 in production environments and apply patches available from the vendor according to references (https://community.openvpn.net/Security%20Announcements/CVE-2025-12106). It is recommended to revert to a stable, supported OpenVPN branch until a fixed version 2.7 is released.

Who is affected

OpenVPN versions 2.7_alpha1 through 2.7_rc1 (inclusive).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
  • Openvpn

    APP
    Openvpn
    2.6.132.7
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
VPN
CWE
References

Related vulnerabilities

CVE-2024-5594CRITICAL9.1PL ✓same product

OpenVPN: Wstrzyknięcie danych przez nieoczyszczone wiadomości PUSH_REPLY

CVE-2024-27903CRITICAL9.8PL ✓same product

OpenVPN dla Windows — ładowanie wtyczek z dowolnego katalogu

CVE-2023-46850CRITICAL9.8PL ✓same product

Use-after-free w OpenVPN 2.6.0–2.6.6 umożliwiający RCE

CVE-2022-0547CRITICAL9.8PL ✓same product

OpenVPN: Authentication Bypass przez wtyczki z odroczoną autoryzacją

CVE-2018-7544CRITICAL9.1PL ✓same product

OpenVPN: cross-protocol scripting przez interfejs zarządzania TCP